CVE-2015-3227: Opensuse
Medium severity, CVSS 5.0. EPSS: 4.3% chance of exploitation in the next 30 days.
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Affected products
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Rubyonrails Rails: version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; version 4.1.3 only; version 4.1.4 only; version 4.1.5 only; …
Published 2015-07-26. Last modified 2026-06-17.